Back to skill

Security audit

lifelog2

Security checks for vulnerabilities and agentic risk

Overview

This diary skill is coherent and disclosed, but users should understand that archived diary entries are sent to flomo and ima and the local draft is removed after successful archival.

Install only if you are comfortable storing diary fragments locally across sessions and sending the compiled diary to flomo and ima when you request archival. Review the summary before archiving, confirm those connected skills use the accounts you intend, and keep a separate copy if you do not want the local draft removed after successful archive.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs archiving diary content to external services (flomo and ima) but does not require an explicit privacy notice or user confirmation about third-party data sharing at the point of export. Because diary entries can contain highly sensitive personal information, users may unknowingly transmit private content outside the local workspace, increasing confidentiality and compliance risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly deletes the local draft file after archiving, but the skill text provides no warning, confirmation step, or indication that the action is irreversible. For a diary skill handling personal content, silent deletion creates a real risk of unintended data loss if archiving fails partially, targets are misconfigured, or the user expected the local copy to remain.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends diary contents to other skills/services during archiving without any privacy notice, consent language, or explanation of where sensitive personal data will go. Because diaries commonly contain intimate thoughts, schedules, and personal events, undisclosed transmission materially increases privacy and confidentiality risk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The page describes a diary skill that records, summarizes, archives to external services, and clears temporary data, but it does not provide any user-facing notice about persistence, third-party sharing, or deletion behavior. Because diary content is highly sensitive personal data, users could unknowingly expose private information to external systems or lose local temporary records without informed consent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The test case normalizes sending diary entries to flomo-notes and ima-skill and then clearing temporary data, yet it gives no warning or consent step for external handling of sensitive journal content. In this context, the skill is specifically designed for fragmented diary logging, so the absence of disclosure increases the risk of privacy leakage and unintended data destruction.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The test result documents that the skill will invoke external skills (flomo-notes and ima-skill), archive user diary content, and clear temporary data, but it does not mention any explicit user warning or confirmation about these data-handling side effects. Because diary entries are sensitive personal data, silently transferring them to other systems and deleting local state can create privacy, consent, and data-loss risks if triggered unexpectedly.

Static analysis

No suspicious patterns detected.